Kohral

Legal

Privacy Policy

This policy explains how PUPUCE CORP processes personal data when you visit Kohral, create an account, sign in with an identity provider, or use the hosted service.

Effective 31 July 2026

Controller

PUPUCE CORP, 16 rue du Patis Pottier, 49250 Loire-Authion, France, SIREN 899 375 869, is the data controller for the hosted Kohral service. Privacy questions and rights requests can be sent to valentin@pupucecorp.com.

Data we process

Account data includes your name, email address, authentication identifiers, organization membership, role, consent choices, and security records. Service data may include agent definitions, runtime and channel configuration, encrypted credentials, conversations, operational metrics, billing references, and support communications that you or your organization choose to provide.

We also process limited technical data needed to operate and secure the service, such as timestamps, request routes, IP addresses, correlation identifiers, application versions, and diagnostic outcome codes. We do not intentionally place raw passwords, secret values, OAuth tokens, or payment-card details in application logs.

Google sign-in data

When you choose Sign in with Google, Kohral requests only the openid, email, and profile scopes. Google provides a stable account identifier, your name, email address, and whether the email is verified. Kohral uses this information only to create, authenticate, and link your Kohral identity.

Kohral does not request access to Gmail, Google Drive, contacts, calendars, or other Google product data. The Google access token is used to complete the sign-in exchange and is not retained after login. The linked Google identifier remains with your Kohral account until the link or account is deleted.

Optional product analytics

Hosted Kohral may use PostHog product analytics only after an explicit opt-in. It records selected product milestones, opaque user, organization, agent, and flow identifiers, runtime or capacity choices, language, application version, HTTP status, and stable technical outcome codes. Autocapture, page-view tracking, session recording, and surveys are disabled.

Analytics events do not contain names, email addresses, messages, prompts, persona text, credentials, secrets, OAuth tokens, payment details, or free-form exception messages. Consent is stored in your browser and, after sign-in, in your Kohral account. You can withdraw it through Analytics preferences. When enabled, events are sent to the configured PostHog EU endpoint.

Purposes and legal grounds

We process data to provide accounts and organizations, deploy and operate the agents you configure, secure the platform, respond to support requests, administer subscriptions, meet legal obligations, and improve opted-in product flows.

The applicable grounds are performance of the service agreement or steps requested before it, compliance with legal obligations, our legitimate interests in security and reliable operations, and your consent for optional product analytics. You may withdraw analytics consent without affecting prior lawful processing or your ability to use Kohral.

Recipients and transfers

Access is limited to authorized PUPUCE CORP personnel and service providers needed for hosting, databases and queues, transactional email, payments, monitoring, support, and consented analytics. Google and GitHub process sign-in interactions when you select them; Stripe processes payment information; PostHog processes opted-in analytics. Each provider processes data under its own terms and our applicable agreement with it.

We do not sell personal data. We may disclose information when legally required, to protect users and the service, or during a business reorganization subject to appropriate safeguards. Hosted production data is operated in an EU region; a provider may process limited data elsewhere under its published transfer safeguards.

Retention

Account and service data is retained while the account or organization is active and for the period needed to close the service, meet legal obligations, resolve disputes, and preserve security records. Linked OAuth identity data is retained until unlinking or account deletion. Billing records may be retained for the legally required accounting period.

Application logs are retained for up to 30 days, security and audit events for up to 90 days, and encrypted backups for up to 30 days under the hosted operating schedule. During the private beta, access, correction, portability, objection, and deletion requests are handled by emailing valentin@pupucecorp.com after identity verification.

Security

Kohral uses access controls, tenant boundaries, encryption for stored credentials and backups, transport encryption, secret redaction, restricted production workloads, and monitored security events. No system is risk-free; please report suspected unauthorized access promptly to valentin@pupucecorp.com.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent at any time. Contact valentin@pupucecorp.com. We may request information necessary to verify your identity and protect other organizations' data.

You may also lodge a complaint with the French data-protection authority, the CNIL, or the supervisory authority in your country of residence or work. Exercising a privacy right does not affect rights or obligations that must be retained by law.

Cookies and browser storage

Kohral uses strictly necessary cookies and browser storage for authentication, security, language, and theme preferences. Optional PostHog persistence is activated only after analytics consent and can be disabled from Analytics preferences. Kohral does not use advertising cookies.

Changes and contact

We may update this policy when Kohral or its providers change. The effective date above identifies the current version. Material changes will be communicated through the service or the contact details associated with your account.